Cross-Site Scripting Vulnerability in Siemens SCALANCE Products
CVE-2018-16555

5.4MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
13 December 2018

Summary

A Cross-Site Scripting vulnerability affects various SCALANCE products due to shortcomings in the integrated web server. This flaw enables potential attackers to execute malicious scripts if an unsuspecting user clicks on a harmful link while logged into the web interface. User interaction is required for the attack to succeed, highlighting the importance of user awareness and vigilance. At the time of this advisory's release, there are no known public exploits targeting this vulnerability.

Affected Version(s)

SCALANCE S602, SCALANCE S612, SCALANCE S623, SCALANCE S627-2M SCALANCE S602 : All versions < V4.0.1.1 < SCALANCE S602 : All versions V4.0.1.1

SCALANCE S602, SCALANCE S612, SCALANCE S623, SCALANCE S627-2M SCALANCE S612 : All versions < V4.0.1.1 < SCALANCE S612 : All versions V4.0.1.1

SCALANCE S602, SCALANCE S612, SCALANCE S623, SCALANCE S627-2M SCALANCE S623 : All versions < V4.0.1.1 < SCALANCE S623 : All versions V4.0.1.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.